Impact
A flaw in CordysCRM’s lead and account retrieval endpoints allows an authenticated user to read records for any lead or account by supplying id check means that standard read permissions grant access to records outside the intended scope. An attacker could obtain contact names, phone numbers, owner, department information, and custom field values for users, departments, or organizations they are not authorized to view.
Affected Systems
CordysCRM 1.7.3 and earlier, released by 1Panel-dev, are affected. The issue was resolved in version 1.7.4, released by 1Panel-dev. Any deployment of the open source CRM prior to this release is vulnerable.
Risk and Exploitability
The vulnerability is scored at CVSS 5.8, indicating moderate severity. Exploitability is not quantified by EPSS or KEV inclusion, but the flaw is straightforward to abuse once an authenticated user gains the CLUE_MANAGEMENT_POOL:READ or CUSTOMER_MANAGEMENT_POOL:READ rights. The likely vector is an authenticated session or API consumer acting with requires only valid credentials and the ability to supply an alternative primary key, it can be performed by any user with the ordinary read permission, making the risk significant for environments with broad read privileges.
OpenCVE Enrichment